{"id":"DEBIAN-CVE-2026-3147","details":"A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been made public and could be used. The patch is identified as b3ab458a25e0e261cbd1788474bbc763f7435780. It is advisable to implement a patch to correct this issue.","modified":"2026-09-01T16:06:37.739991779Z","published":"2026-02-25T04:16:05.670Z","upstream":["CVE-2026-3147"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-3147"}],"affected":[{"package":{"name":"vips","ecosystem":"Debian:12","purl":"pkg:deb/debian/vips?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.14.1-3+deb12u3"}]}],"versions":["8.14.1-3","8.14.1-3+deb12u1","8.14.1-3+deb12u2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-3147.json"}},{"package":{"name":"vips","ecosystem":"Debian:13","purl":"pkg:deb/debian/vips?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.16.1-1+deb13u1"}]}],"versions":["8.16.1-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-3147.json"}},{"package":{"name":"vips","ecosystem":"Debian:14","purl":"pkg:deb/debian/vips?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.18.0-3"}]}],"versions":["8.16.1-1","8.16.1-2","8.17.3-1","8.17.3-2","8.18.0-1","8.18.0-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-3147.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}